Find out if you have vulnerabilities that put you at risk

Test your applications
Toggle filtering controls
Report a new vulnerability
VULNERABILITYAFFECTSTYPEPUBLISHED
  • C
Credential Exposure
thorsten/phpmyfaq<4.0.0Composer11 Dec 2024
  • M
SQL Injection
nette/database>=0.0.0Composer11 Dec 2024
  • H
Inefficient Algorithmic Complexity
league/commonmark<2.6.0Composer10 Dec 2024
  • C
Improperly Controlled Modification of Dynamically-Determined Object Attributes
drupal/core>=8.8.0, <10.2.11>=10.3.0, <10.3.9Composer10 Dec 2024
  • C
Improperly Controlled Modification of Dynamically-Determined Object Attributes
drupal/core>=8.8.0, <10.2.11>=10.3.0, <10.3.9>=11.0.0, <11.0.8Composer10 Dec 2024
  • C
Improperly Controlled Modification of Dynamically-Determined Object Attributes
drupal/core>=8.8.0, <10.2.11>=10.3.0, <10.3.9>=11.0.0, <11.0.8Composer10 Dec 2024
  • H
Improper Handling of Case Sensitivity
drupal/core>=8.8.0, <10.2.11>=10.3.0, <10.3.9>=11.0.0, <11.0.8Composer10 Dec 2024
  • M
Cross-site Scripting (XSS)
drupal/core>=8.8.0, <10.2.11>=10.3.0, <10.3.9>=11.0.0, <11.0.8Composer10 Dec 2024
  • M
Incomplete List of Disallowed Inputs
winter/wn-system-module<1.2.7Composer10 Dec 2024
  • M
Incomplete List of Disallowed Inputs
winter/wn-cms-module<1.2.7Composer10 Dec 2024
  • M
Cross-site Scripting (XSS)
drupal-pattern-lab/add-attributes-twig-extension>=0.0.0Composer9 Dec 2024
  • L
Cross-site Scripting (XSS)
drupal-pattern-lab/bem-twig-extension>=0.0.0Composer9 Dec 2024
  • M
Cross-site Scripting (XSS)
drupal-pattern-lab/unified-twig-extensions>=0.0.0Composer9 Dec 2024
  • L
Cross-site Scripting (XSS)
pattern-lab/drupal-twig-components>=0.0.0Composer9 Dec 2024
  • M
Server-side Request Forgery (SSRF)
j0k3r/httplug-ssrf-plugin>=0.0.0Composer9 Dec 2024
  • M
Cross-site Scripting (XSS)
aptoma/twig-markdown>=0.0.0Composer9 Dec 2024
  • H
Infinite loop
drupal/core>=10.1.0, <10.1.8>=10.2.0, <10.2.2Composer6 Dec 2024
  • H
Detection of Error Condition Without Action
drupal/core>=10.0.0, <10.2.10Composer6 Dec 2024
  • M
Cross-site Scripting (XSS)
librenms/librenms>=24.9.0, <24.10.1Composer6 Dec 2024
  • M
Cross-site Scripting (XSS)
samwilson/unlinked-wikibase>=1.0.0, <2.0.0Composer5 Dec 2024
  • H
XML External Entity (XXE) Injection
simplesamlphp/simplesamlphp<2.0.15>=2.1.0, <2.1.7>=2.2.0, <2.2.4>=2.3.0, <2.3.4Composer3 Dec 2024
  • H
XML External Entity (XXE) Injection
simplesamlphp/xml-security<1.10.0Composer3 Dec 2024
  • H
XML External Entity (XXE) Injection
simplesamlphp/xml-common<1.20.0Composer3 Dec 2024
  • H
XML External Entity (XXE) Injection
simplesamlphp/saml2-legacy<4.6.14Composer3 Dec 2024
  • H
XML External Entity (XXE) Injection
simplesamlphp/saml2<4.6.14>=5.0.0-alpha.1, <5.0.0-alpha.18Composer3 Dec 2024
  • M
Cross-site Scripting (XSS)
ibexa/admin-ui>=4.6.0, <4.6.14Composer1 Dec 2024
  • H
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
spencer14420/sp-php-email-handler<1.0.0Composer28 Nov 2024
  • M
Files or Directories Accessible to External Parties
tecnickcom/tcpdf<6.7.6Composer27 Nov 2024
  • M
Directory Traversal
statamic/cms<5.17.0Composer20 Nov 2024
  • M
Cross-site Scripting (XSS)
redaxo/source<5.18.0Composer20 Nov 2024